Re: [D] Threat model: how should Thread Context (MDC) keys be classified (trusted structural or untrusted content) ? [logging-log4j2]

vy (via GitHub) <[email protected]> Mon, 01 Jun 2026 14:08:34 -0000
Newsgroups gmane.comp.jakarta.log4j.devel
Message-ID <ghd-D_kwDOAKJSSM4AmyP1-f1ccb200-b976-4b6a-b38e-deb090a51982@gitbox.apache.org>
GitHub user vy added a comment to the discussion: Threat model: how should Thread Context (MDC) keys be classified (trusted structural or untrusted content)?

@FreeAndNil has captured it nicely. I agree with all his remarks.

GitHub link: https://github.com/apache/logging-log4j2/discussions/4132#discussioncomment-17136813

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]